๐บ๐ธ
TPI-Abuse
2026-10-07 08:31:24
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:31:17.832366 2026] [security2:error] [pid 27442:tid 27442] [client 191.102.129.149:62159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hppagewidetampa.com"] [uri "/.git/HEAD"] [unique_id "asYDVVVQ3jrgVkJR1RXgvgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:08:05
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:07:59.436288 2026] [security2:error] [pid 18020:tid 18020] [client 191.102.129.149:59935] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "asRX_9obkf4HoBqyy6JxYQAAAAM"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 00:30:12
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:30:07.054777 2026] [security2:error] [pid 15785:tid 15785] [client 191.102.129.149:41935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brunswickcemeteries.org"] [uri "/.git/HEAD"] [unique_id "aq3Xj9DXGJLxwuaZtdGPugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-09-15 08:04:10
(3 weeks ago)
[15/Sep/2026:10:04:09.329392 +0200] aqj7-eJIncjEFg0s9ERYugAAAAA 191.102.129.149 37594 127.0.0.1 7081 ...
show more
[15/Sep/2026:10:04:09.329392 +0200] aqj7-eJIncjEFg0s9ERYugAAAAA 191.102.129.149 37594 127.0.0.1 7081
[15/Sep/2026:10:04:09.977060 +0200] aqj7-WN_R96lGtl6EeFvWwAAAAE 191.102.129.149 42074 127.0.0.1 7081
[15/Sep/2026:10:04:10.642196 +0200] aqj7-g_vkdl31mEaxJ9bogAAAAg 191.102.129.149 42086 127.0.0.1 7081
...
show less
Hacking
๐ต๐ฑ
Budyn
2026-09-14 17:31:57
(3 weeks ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: Boto3/1.42.60 md/Botocore#1.42.60 ua/2.1 os/linux#5.15.0-191-generic md/arch#x86_64 lang/python#3.10.12 md/pyimpl#CPython m/e,Z,b,E cfg/retry-mode#standard B...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-12 04:35:41
(3 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: /tel:5012760688 | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 | 2026-09-12 04:35 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
dtorrer
2026-09-08 19:25:59
(4 weeks ago)
Client attempted to submit spam on a website post.
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-09-06 15:47:19
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:47:12.031105 2026] [security2:error] [pid 9818:tid 9818] [client 191.102.129.149:43231] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edgecomix.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edgecomix.com"] [uri "/mailto:[email protected] "] [unique_id "ap2LAEmhcgYvyTF3RSSBtAAAAA8"], referer: https://edgecomix.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 03:10:11
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:10:03.113396 2026] [security2:error] [pid 19398:tid 19398] [client 191.102.129.149:38223] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apeTixzksKTrhAJ2iuD-5AAAABg"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:19:14
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:19:09.611094 2026] [security2:error] [pid 6177:tid 6177] [client 191.102.129.149:59691] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "apIlff5IurDqTS5zVglWywAAAAw"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 09:54:03
(2 months ago)
FortiWeb WAF: 30 attacks detected. Threat Score: 11314155. Types: Client Management(15), Signature D ...
show more
FortiWeb WAF: 30 attacks detected. Threat Score: 11314155. Types: Client Management(15), Signature Detection(15). Origin: United States.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 16:35:53
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 12:35:47.385408 2026] [security2:error] [pid 3161:tid 3161] [client 191.102.129.149:31607] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ahxjYwmRrNgFtwIm-XZ-mAAAAAY"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-10 01:13:19
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-24 01:52:54
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 21:52:46.568389 2026] [security2:error] [pid 22637:tid 22637] [client 191.102.129.149:41309] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "acHubpmsQy-Udd5-kuxQwwAAABU"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 15:45:44
(7 months ago)
ban-reviewer auto report; ip=191.102.129.149; scenario=http:scan; verdict=valid_ban; confidence=0.85 ...
show more
ban-reviewer auto report; ip=191.102.129.149; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); Decision was made by CAPI with 9960m duration (nearly 7 days); AbuseIPDB context indicates port scan and hacking categories are relevant
show less
Port Scan
Hacking
Brute-Force